your opinion on this outgoing acl?

Hello

I put the following ACL inside the interface of our PIX 525, v6.3 (5).

The goal is to prevent our network to pollute the rest of the world with Korgo.

It's my first 'from scratch' ACL (that I administer a system that has been installed by others).

You will notice that there is a "permit ip any any", then later there "deny ip any any".

It's because I'm confused about the scope of the Protocol parameter. TCP, UDP, ICMP, ESP, IP, all have their own protocol numbers. But, I know that designating IP include TCP and UDP.

Specifying the IP address in the Protocol setting an ACL includes ALL issues of Protocol?

If this is the case, my "license ip any any" statement ensures that I'm not blocking any outgoing traffic I want to allow. (This is my main concern - ensure that I don't have anything that I shouldn't be blocked inadvertently, and with the statement of ip deny, I will get hitcounts if I am away it fake...)

THX...

Linnea

allowed for acl_outbound of access list row 1 tcp 10.0.0.0 255.0.0.0 209.129.196.0 255.255.255.0 eq 445 (hitcnt = 1)

acl_outbound of access list row 2 tcp refuse any any eq 3067 (hitcnt = 0)

acl_outbound of access list row 3 tcp refuse all all ident eq (hitcnt = 0)

line of acl_outbound to access list refuse 4 tcp any any eq 445 (hitcnt = 6)

acl_outbound L5 of the ip access list permit all a (hitcnt = 48537)

allowed to access list acl_outbound line 6 icmp any a (hitcnt = 0)

acl_outbound of access line list 7 deny ip any a (hitcnt = 0)

Linnea

Yes, I think you have the concept now. The protocols listed on the IANA page are layer 4 protocols that run over IP. When you specify IP you intrinsically get each of them.

A picky point: on your return, that intellectual property is not a Protocol, the IP is a protocol. It is a layer 3 protocol that runs on Ethernet or HDLC frame relay, etc.. When you create a list of IP access, IP is the basic protocol, and if you specify IP so you get everything that is built on this basis.

HTH

Rick

Tags: Cisco Security

Similar Questions

  • What is your opinion on the ipad hotpoint

    I am planning to use a hotpoint for my business. I was wondering what kind of experience I would using the Ipad hotpoint. Is it fast, ok, slow. Y at - it somebody who uses it and what is your opinion.

    Thank you

    Assuming that you are referring to the hotspot feature, nobody here can tell how it works because it depends on your wireless provider, congestion on the network, signal strength, etc...

    Peronsally, I would not even consider this route.

  • Need your opinion on Equium A100-147

    IM thinking about purchasing one of them and I was wondering what others thought of him. It looks like great value at £500. the machine will also be able to upgrade to windows Vista premium edition?

    Hello Mark

    In my opinion, because this money, the unit is very nice but he should know very well what you expect of your laptop and what you want to do with it. For all day use the device is perfect, but if you want some high graphic performance I believe it is the right one.

    On this forum, I noticed many buy units with the hardware configuration users fairly even and later to upgrade CPU, graphics card, HARD drive put an end to their efforts. I think that you should from the outset be sure that what you have and buy the right unit.

    Please check with the dealer if the unit has label Vista capable. If yes the Vista installation will not be problem.

  • PSE13 Validation impossible serial No.; recognition binding not blocking on the Internet; launch PSE13: result page white; However N ° license registered in profile; give your opinion? not of I don't know! What do I do? Thank you

    PSE13 Validation impossible serial No.;

    recognition binding not blocking on the Internet;

    If/reinstal: Ditto

    launch PSE13: result page white;

    However N ° license registered in profile; give your opinion? not of I don't know!

    What do I do? Thank you

    Hi Jpl81406915,

    Please visit:https://helpx.adobe.com/x-productkb/policy-pricing/activation-network-issues.html

    I hope this helps.

    Concerning

    Megha Rawat

  • The page you are looking for is not available. You may need to contact your administrator with this error: 404 Page not found.

    I am at a loss.  I've set up a root certification authority to sign all servers in my workspace of Horizon, SAML is in the Green and after a lot of reading when troubleshooting also synchronized on all my ESXi hosts and guests.

    Basically, what I did is the following:

    Set up the connection to the Server VMware View Horizon 5.2 - created different pools and can connect via the customer different platform. (a few times to eliminate any possible configuration errors along the way)

    Configuration of VMware View Horizon Workspace 1.0 (a few times now) with self-signed and CA signed certs.  My workspace appears fine, the synchronization of files, apps work, and view pools appear.  When I try to launch your desktop from inside the Horizon workspace I get this error:

    The page you are looking for is not available. You may need to contact your administrator with this error: 404 Page not found.

    Now I think that I followed it down to something to do with SAML connection - which, to my understanding, archery chips between workspace and view.  On the login server, I see it in the Windows event log:

    BROKER_USER_AUTHFAILED_SAML_ACCESS_REQUIRED

    SAML access required but not tempted by customer

    Attributes:

    Source = com. VMware.VDI.Broker.filters.SamlAuthFilter

    Time = MON may 20 16:06:41 MDT 2013

    Gravity = AUDIT_FAIL

    Node = ViewConnection.access360.ca

    Module = broker

    Recognized = true

    Something is not crossing to allow me to access my office view since the workspace of Horizon.  If I remove the requirement of SAML on the login server see, when I try to connect to a desktop computer from the view connection server I get a promotion for and can I get my IDs & field and have full access with reviews, as well as blast HTML - just cannot get there with Horizon Workspace.  There must be something that I am missing with SAML...

    As I said, I'm at a loss here on what does not work between the Horizon workspace and the connection of SAML for display to connect to the server.  There is no server security, server transfer, and firewalls is all off, so I don't think it's a network problem.  Simple as possible.  The Windows Journal event displays the login displays server error is: access required but not attempted by client SAML.  I have all my servers synchronized after a few seconds - so I don't think that documented the TIME Horizon workspace synchronization time sensitivity is responsible here.  I am Pack overnight, but will do exactly the same thing with a client of tomorrow - hopefully without the same result!

    Any ideas?

    A

    So I re-deployed the VAPP (again!) very attentive as I went.  As usual, the initial database installation failed because I entered my domain FULL of the gateway name, so it does not match.  After useful messages already there for this (Workspace install fails with error creating the user admin) I used the wizardssl.hzn of connfigurator - going to recreate a rootca to the environment based on my FULL domain instead of the bridge - going and then let it grow all for the other vApps.  I then connected to each and pulled down my private rootca and ran c_rehash, etc. (another useful message!- adding MS signed Certs to Horizon Workspace & laquo;) Carlos & #039; Corner) I actually use my background to UNIX and openssl to be my own private CA and sign all of my certificates.  I created the SAN cert and added to the SSL configuration on the Configurator - going and connector - going.  Oddly enough, both of these server do not appear to be accepting SAN cert that includes their ENTIRE domain, but that's for another day... My Horizon Workspace FQDN does show as being approved by installed RootCA private (which does not have other DNS names for the service - going, the Configurator - goes, the data - will and the connector - will, but as I have already said--a battle for another day) so it's a good thing.  I joined my workspace to my domain name - well!  Activated would be pools seen in the Configurator - goes - sync - good.  CRT for the my display login server has accepted and implemented the SAML trust.  Still good.  Sync in my opinion users group who already had a couple of linked clone pools allowed to do.  Good.  Connected to the FQDN of my workspace and clicked on computers - seen my 3 pools.  Clicked on one and after a few seconds, launched in a new window of the explosion.  Success!  I disconnected and connected on a different machine, and something that I saw before, but doesn't have a lot of attention to was the connector - will put 'use windows authentication', I couldn't understand why every time I sailed on my Horizon workspace a no vmware window opens asking access my FQDN:443 with a user and pass.  It is this setting - duh.  I'm not sure yet that gives me, so it's off for now.

    Thanks for all the input: it's good to know that there are others with some of the same questions.  It's still v1.0, it is related to some of these pitfalls.  It is capricious with derived from same time less than 10 seconds seems to have a negative impact.  Had to ensure my ESXi servers were strong (never worried a lot in the past with MS AD being quite tolerant with small derivatives) I tired my vApps affecting a NTP, but they seemed like being left to the default of synchronization to the ESXi host.  See how than pans.  CERT is somewhat capricious depending on your deployment.  Of course the connector - will and the Configurator - must be signed by a CA that they are internal, but always be nice to then have signed internal...

    Now, I'm on ThinApps for desktops as well as the web interface integration.

    I bumped my head against the wall with my first configuration of Citrix XA and XD (before having VDI in a box!) and it was the best way to learn.

    I don't know that I grave along that I finished my PoC, but I'm very happy with today's results.  I still plan on the comparison of my logs successful with the logs I have pulled my former deployment TIME and see what it was that it was broken.  I think it was that wanted me a PTR record to my domain FULL DNS MS. name  I think I just had the direct search for the original bridge - will and FULL, but only a setback for the gateway domain - name.  Would explain why I was never able to connect to the gateway to access your desktop.  Oops.

    A

  • with the auto more recent updated version of firefox now there is a white bar that appears when you move your mouse over this area. I want that gone, how?

    When you move your mouse below the address bar opens a white bar, making it so you can't click on buttons or links on sites, like buttons connection for example. also when using the full screen, you can no more mouse on the tabs at the top of the screen, only this white bar appears. This prtty much kills its use full screen for me. Thus, this white popup bar and mode full screen with the white bar without tabs firefox has pretty much ruined it for me. in any case to fix it would be great.

    Launch Firefox in Mode safe

    While you are in safe mode;

    Firefox Options > advanced > General.

    Find and stop using hardware acceleration.

    ===================================

    Hello

    To better help you with your question, please provide us with a screenshot. If you need help to create a screenshot, please see How to make a screenshot of my problem?

    Once you have done so, attach the file to screen shot saved to your post on the forum by clicking on the button Browse... under the box to post your reply . This will help us to visualize the problem.

    Thank you!

  • This site provides information to identy that your connection to this site is not encrypted. How can I fix this so I can log in on the site that I need to use?

    This site does not provide any identity information
    Your connection to this site is not encrypted.
    This message keeps coming up everytime I try to connect to this site using my user name and password for the site. I can connect from my desktop, but I can't connect from my laptop. Please help with this problem, if anyone can.

    This doesn't seem to be a valid web address.

    http://store-ePromo.com

  • Trying to get on my email, the following statement comes from the IPU: "we're sorry, but you must enable cookies and Javascript to use your username with this site. I click on "here", but nothing happens. How to enable the amd Javascript cookies?

    Try to get t my email, this happens: we're sorry, but you must enable cookies and Javascript to use your username with this site.
    How can I do this?

    George Szántó

    [email protected]

    see similar question answered https://support.mozilla.com/questions/836913

    To be notified of updates to a question, if this is your problem or not just click on the "Get email notifications" and follow made the choice. Only the original poster can mark it as resolved, so there should be a slight difference in choice as an original poster and where you lock on another issue. Notifications only apply to individuals the question where is entered.

  • Your opinion on Qosmio X 770-107

    Hi guyz,

    I had the bad experience with qosmio before, atm I'm looking for the new machine. I ask you on what is your opinion on Qosmio x 770-107.

    Also, don't mind suggestion of other laptop too which works very well.

    Nobody does not censor you or someone else.
    http://forums.computers.Toshiba-Europe.com/forums//message.jspa?MessageID=249707

  • Should I upgrade my macbook pro at el capitan 2015? How is the performance on elcapitan? give your opinion! Thank you :D

    Should I upgrade my macbook pro at el capitan 2015? How is the performance on elcapitan? give your opinion! Thank you

    My iMac with 8 GB or RAM 2011 works very well with the 10.11.2 was last updated. It is up to you to decide. It should work perfectly on almost any new machine of 2015.

  • Impossible to uninstall a program; error message: sorry you do not have the right permissions tocomplete this action. Please contact your administrator on this computer to continue

    I downloaded a program on the internet, but now when im trying to uninstall it is showing this error message: cannot uninstall a program. error message: sorry you do not have the right permissions tocomplete this action. Please contact your administrator on this computer to continue. What should I do please help.

    Hello

    you tell us the name of the program

    go to the website of manufacturers of programs and to find a way to uninstall

    or try this free program for her

    http://www.revouninstaller.com/

    and it is a program 'downloaded a program from the internet' search for malware

    Download update and scan with the free version of malwarebytes anti-malware

    http://www.Malwarebytes.org/MBAM.php

    You can also download and run rkill to stop the process of problem before you download and scan with malwarebytes

    http://www.bleepingcomputer.com/download/anti-virus/rkill

    If it does not remove the problem and or work correctly in normal mode do work above in safe mode with networking

    Windows Vista

    Using the F8 method:

    1. Restart your computer.
    2. When the computer starts, you will see your computer hardware are listed. When you see this information begins to tap theF8 key repeatedly until you are presented with theBoot Options Advanced Windows Vista.
    3. Select the Safe Mode with networking with the arrow keys.
    4. Then press enter on your keyboard to start mode without failure of Vista.
    5. To start Windows, you'll be a typical logon screen. Connect to your computer and Vista goes into safe mode.
    6. Do whatever tasks you need and when you are done, reboot to return to normal mode.
  • BlackBerry Smartphones Blackberry Podcasts - error after having reinstalled 'Podcasts service does not support your carrier on this unit.

    I uninstalled Blackberry Podcasts a few days ago, and then re-installed. After that, I am now presented with this error message at the launch of the app: "Podcasts service does not support your carrier on this device" I tried several times to uninstall/reinstall. This error message is not sensible for me because it was working fine when I had installed originally there. James.

    I'm located in the Canada. Installation of the v1.5.0.47 (unreleased/non official) solved the problem. Not clear what it is, maybe the official version was incompatible with my new Blackberry 9900.

  • Frequent error pop up: a website wants to open web content using this program on your computer. This program is not a valid signature that verifies its publisher.

    Original title: frustrating popup.

    Help! I get the following popup:

    A website wants to open web content using this program on your computer.  This program does not have a valid signature that verifies its publisher

    C:|Windows/System32\Macromed\Flash/FlashUtil_ActiveX.exe

    Why I get this and how can I get rid of him?  It won't go away if I answered 'yes' or 'no' it just keeps popping up.

    Windows 8 is built with Adobe Flash Player. If you have problems to view Flash content online, run Windows Update and check if there are updates available for Flash.

    You can also try the following:

    Click Start, type: Internet Options

    Press enter

    Select the "Advanced" tab

    Under reset Internet Explorer settings, click "reset".

    This should restore the Internet Explorer default settings.

    Or try another browser like Google Chrome.

  • Windows installation was not successful. Your previous version of Windows is being restored. Do not restart your computer during this time.

    Windows installation was not successful. Your previous version of Windows is being restored. Do not restart your computer during this time.     I have a small Toshiba laptop which has installed Windows 7.  I uninstalled my Norton (that I was instructed to do so by a friend); tried to reinstall Windows 8; and got the same message.  Any suggestions?

    Hi Dreah117,

    Thanks for choosing Windows 8!

    I understand that you get this error trying to upgrade to Windows 8. Its good that
    you have removed your anti-virus software are there is a possiblity of it
    causing problems with installation

    I have a few questions about your system

    1. what operating system (OS) you upgrade?
    2 what is a 32 or 64 bit OS?
    3. you try to install a 32-bit or 64-bit of Windows 8?

    You can try these methods to see if it solves the problem

    Method 1:
    Run the upgrade wizard and check to see if your system is compliant with the minimum requuirements.

    http://Windows.Microsoft.com/en-us/Windows-8/upgrade-to-Windows-8

    Method 2:
    Disable or uninstall a software such as CD/DVD burning utility or third-party disk utility to defragment programs such as perfect disk / Daemon Tools

    (a) in the notification area, next to the time looking for icons of software disk utility

    (b) pass the mouse over it to check the name

    (c) right-click on the icon and select "Exit/Disable" or a similar option.

    Method 3:
    Make sure your computer is updated through Windows Update.

    http://Windows.Microsoft.com/en-us/Windows7/products/features/Windows-Update

    Method 4:

    Disconnect all unnecessary external devices such as printers / joysticks etc.

    Method 5:
    Put the computer to boot is a way to solve problems

    http://support.Microsoft.com/kb/929135

    Note: Please follow step 3 on the link if upgradation fails to return your system to a normal startup.

    We know what's going on and if we can be of any other assistance.

  • Dialog box that says ' Creative Cloud Installer wants to make changes. Type your password for this purpose"- I type my password for Adobe ID (creative cloud), but it will not accept it. who should I go for help with this query?

    Dialog box that says ' Creative Cloud Installer wants to make changes. Type your password for this purpose"- I type my password for Adobe ID (creative cloud), but it will not accept it. who should I go for help with this query?

    It does not ask the cloud your computer admin password password!

Maybe you are looking for

  • 5.6.1 Pages using: can't see the JPEGs created in Pages 09

    My scanner is connected to an iMac G5 running 09 Pages.  I scan images in JPEG format, erase the background using magic in Photoshop 3 gum, paste them into a document Pages 09, set them to float and then e-mail the 09 Pages to my MacBook Pro mid 2012

  • Problem incrementing in a worksheet

    I recently discovered a new problem while trying to increment per line in a worksheet. The problem is when I try to rank 9 to 10 (single two-digit) increment, it increments to ': ' there is no! Similarly, when I try to go from rank 10 to 11 it increm

  • I have windows 98, I'm trying to update to install windows xp from a used cd, I need numbers installion how their

    I have windows 98, I'm trying to update to install windows xp from a used cd, I need numbers installion how their

  • Help menu persistence virus?

    I have a hp laptop 2008 running windows vista and everytime I open anything. No matter what is a Minesweeper of antivirus for internet browsers to word documents in the Task Manager, the Help window appears and don't go away or even go to the backgro

  • Box: BBC and Silverlight

    When I try to add the BBC News Widget to my sidebar I get a notice that says "this gadget requires Microsoft Silverlight.  Click to install, add new gadget".  I have Silverlight running.  But I have reinstalled in all cases, restarted my browser, BBC